OpenID Connect connects any issuer that publishes a discovery document. The form is the same OIDC connection Microsoft Entra ID and BeyondTrust use. Authdog routes users by email domain.

## Open the connection

In the [Authdog console](https://console.authdog.com/dashboard/authentication?tab=providers&category=enterprise):

1. Select the project and environment.
2. Open **Authentication > Providers** with the Enterprise filter.
3. Choose **OpenID Connect**.
4. Copy the redirect / callback URL Authdog displays and register it on the issuer as a web redirect URI.

## Configure the issuer

| Field | Value |
| --- | --- |
| **Connection name** | A name that shows in the Configured list |
| **Connection Mode** | **External (Remote provider)** for an issuer you do not run as an Authdog OIDC client |
| **OpenID Connect Discovery URL** | The URL of the discovery document, not a bare issuer that does not serve it |
| **Client ID** | The client registered at the issuer |
| **Authentication Method** | **Client Secret**, unless the issuer requires **Private Key JWT** |
| **Client secret** | Stored encrypted. Leave blank on a later edit to keep the stored secret |

For **Private Key JWT**, provide the **Private Key (PEM)** and **Signing Algorithm** (`RS256`, `RS384`, or `RS512`) instead of a client secret.

**Internal (Select OIDC Client)** uses an OIDC client already registered in this environment. Pick that client in **OIDC Client** and skip the discovery URL.

Scopes default to `openid profile email`. Add an extra scope only when a claim you need requires it. Leave **Prompt** on the issuer default unless you need an account picker or a forced re-authentication.

## Route by email domain

In **Email domains (for SSO discovery)**:

```text
acme.com
```

The entry matches that domain and its subdomains. Keep domains from overlapping other enterprise connections in the same environment. Only active connections participate in discovery.

## Test it

1. Use **Test** on the connection.
2. Sign in with a user in the routed domain and confirm the subject and email claims.
3. Repeat in production. If you add a [custom domain](/docs/custom-domains), update the redirect URI on the issuer with the URL shown in the form.

Named vendors with the same form: [Microsoft Entra ID](/marketplace/entra/setup) and [BeyondTrust](/marketplace/beyondtrust/setup).

## Related

| Read | To learn how to |
| --- | --- |
| [Enterprise SSO](/docs/sso) | Discovery, domain routing, and secrets |
| [SAML 2.0](/marketplace/saml/setup) | When the IdP speaks SAML instead of OIDC |
| [Marketplace](/marketplace/openid-connect) | The listing for this integration |
